Threat actors targeting Retail & E-Commerce
Part of Threatwake, a free morning threat-intelligence dashboard.
8 threat actor groups tracked in MITRE ATT&CK are documented as targeting retail & e-commerce, between them using 200 distinct ATT&CK techniques. 10 retail & e-commerce victims appear in the current ransomware leak-site feed.
Most-used ATT&CK techniques against retail & e-commerce
- T1059.001 · PowerShell (execution) — used by 7 of 8 retail & e-commerce actors (88%)
- T1105 · Ingress Tool Transfer (command-and-control) — used by 7 of 8 retail & e-commerce actors (88%)
- T1588.002 · Tool (resource-development) — used by 7 of 8 retail & e-commerce actors (88%)
- T1021.001 · Remote Desktop Protocol (lateral-movement) — used by 6 of 8 retail & e-commerce actors (75%)
- T1059.003 · Windows Command Shell (execution) — used by 6 of 8 retail & e-commerce actors (75%)
- T1553.002 · Code Signing (defense-impairment) — used by 6 of 8 retail & e-commerce actors (75%)
- T1047 · Windows Management Instrumentation (execution) — used by 5 of 8 retail & e-commerce actors (63%)
- T1053.005 · Scheduled Task (execution) — used by 5 of 8 retail & e-commerce actors (63%)
- T1078 · Valid Accounts (stealth) — used by 5 of 8 retail & e-commerce actors (63%)
- T1082 · System Information Discovery (discovery) — used by 5 of 8 retail & e-commerce actors (63%)
- T1087.002 · Domain Account (discovery) — used by 5 of 8 retail & e-commerce actors (63%)
- T1486 · Data Encrypted for Impact (impact) — used by 5 of 8 retail & e-commerce actors (63%)
Threat actor groups
- APT41 (also: Wicked Panda, Brass Typhoon, BARIUM) — 82 documented techniques
- FIN7 (also: GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS) — 67 documented techniques
- Scattered Spider (also: Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944) — 64 documented techniques
- FIN13 (also: Elephant Beetle) — 53 documented techniques
- FIN6 (also: Magecart Group 6, ITG08, Skeleton Spider, TAAL) — 40 documented techniques
- FIN8 (also: Syssphinx) — 36 documented techniques
- TA505 (also: Hive0065, Spandex Tempest, CHIMBORAZO) — 34 documented techniques
- Winnti Group (also: Blackfly) — 6 documented techniques
Ransomware groups currently hitting retail & e-commerce
10 victims claimed in the current feed.
- Global Secret Group — 5 victims
- safepay — 3 victims
- qilin — 1 victim
- Deadlock — 1 victim
Threat intelligence by sector
- Healthcare
- Financial Services
- Government & Defense
- Technology
- Manufacturing
- Energy & Utilities
- Education
- Transportation
- Professional Services
- Agriculture & Food
- Hospitality
Actor and technique data is reference intelligence from MITRE ATT&CK v19.1 and the MISP galaxy — curated knowledge describing historically observed targeting, refreshed a few times a year. Ransomware and news are live feeds. Threatwake labels which is which throughout.